首页> 外文会议>International Conference on Network and System Security >CloudSec: A security monitoring appliance for Virtual Machines in the IaaS cloud model
【24h】

CloudSec: A security monitoring appliance for Virtual Machines in the IaaS cloud model

机译:CloudSec:IAAS云模型中虚拟机的安全监控设备

获取原文

摘要

The Infrastructure-as-a-Service (IaaS) cloud computing model has become a compelling computing solution with a proven ability to reduce costs and improve resource efficiency. Virtualization has a key role in supporting the IaaS model. However, virtualization also makes it a target for potent rootkits because of the loss of control problem over the hosted Virtual Machines (VMs). This makes traditional in-guest security solutions, relying on operating system kernel trustworthiness, no longer an effective solution to secure the virtual infrastructure of the IaaS model. In this paper, we explore briefly the security problem of the IaaS cloud computing model, and present CloudSec, a new virtualization-aware monitoring appliance that provides active, transparent and real-time security monitoring for hosted VMs in the IaaS model. CloudSec utilizes virtual machine introspection techniques to provide fine-grained inspection of VM's physical memory without installing any monitoring code inside the VM. It actively reconstructs and monitors the dynamically changing kernel data structures instances, as a prior step to enable providing protection for kernel data structures. We have implemented a proof-of-concept prototype using VMsafe libraries on a VMware ESX platform. We have evaluated the system monitoring accuracy and the performance overhead of CloudSec.
机译:基础设施 - AS-Service(IAAS)云计算模型已成为一个引人注目的计算解决方案,并经过验证的能力,降低成本并提高资源效率。虚拟化在支持IAAS模型方面具有关键作用。但是,由于通过托管虚拟机(VM)的控制问题丢失,因此虚拟化也使其成为有效rootkits的目标。这使得传统的客人安全解决方案,依赖于操作系统核值得信赖性,不再是确保IAAS模型的虚拟基础设施的有效解决方案。在本文中,我们简要介绍了IAAS云计算模型的安全问题,并呈现了一个新的虚拟化感知监视设备,为IAAS模型中为托管VM提供了主动,透明和实时安全监控。 CloudSEC利用虚拟机进入技术为VM物理内存提供细粒度检查,而无需在VM内安装任何监视代码。它主动地重建并监视动态变化的内核数据结构实例,作为能够为内核数据结构提供保护的现有步骤。我们在VMware ESX平台上使用VMSAFE库实施了概念验证原型。我们已经评估了系统监视准确性和CloudSec的性能开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号